BC & DR Flashcards

1
Q

What does BCP deal with?

A

Keeping business operations running

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does DRP deal with?

A

Restoring normal business operations after the disaster tales place

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are three common elements between BCP and DRP?

A
  • Identification of critical business functions
  • Identification of disaster scenarios
  • Experts
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What two assessments are commonly used to identify critical business functions?

A
  • Business Impact Assessment

- Vulnerability Assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What two elements are commonly used to rank possible disaster scenarios?

A

Probability and Impact

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What term is used to describe the blending of BCP and DRP into a single mission?

A

COOP (Continuity of Business Operations)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are 3 important elements of a BCP project?

A
  • Senior Management Support
  • Senior Management Involvement
  • Project Team Membership
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A BCP project generally consists of which 4 components?

A
  • scope determination
  • BIA
  • BCP
  • Implementation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the term used to describe a project scope when it grows beyond the original intent?

A

Scope Creep

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What type of assessment would you carry out determine which business functions are more resillient and which are more fragile?

A

Business Impact Assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How are the effects of an impact generally categorised?

A

Quantitative and Qualitative

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What 5 tasks need to be performed well as part if a Business Impact Assessment?

A
  1. Perform a Vulnerability Assessment
  2. Carry out a criticality assessment
  3. Determine the maximum tolerable downtime
  4. Establish recovery targets
  5. Determine resource requirements
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a criticality assessment?

A

Determines how critically important a particular business function is to the ongoing viability of the organisation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What type of assessment determines the impact, both quantitative and qualitative - of the loss of a critical business function?

A

Vulnerability Assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which type of assessment should identify critical support areas?

A

vulnerability assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the steps in a criticality assessment?

A
  1. Inventory all high level business functions and rank them in order of criticality
  2. Describe the impact of a disruption to each function on overall business operations.
  3. Estimate the duration of a disaster event
  4. Consider the impact of a disruption based on the length of time that a disaster impairs critical business functions.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What does MTD stand for in relation to BCP?

A

Maximum Tolerable Downtime

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What are the two objectives when assessing recovery targets?

A

Recovery Time Objective

Recovery Point Objective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What term is used to describe the maximum period of time in which a business process must be restored after a disaster?

A

Recovery Time Objective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What term is used to describe the maximum period of time in which data might be lost if a disaster strikes?

A

Recovery Point Objective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

4 typical resource requirements are:

A
  • IT Systems and application
  • Key personnel
  • Business equipment
  • Supplier and Partners
22
Q

What is the businesses highest priority in the event of a disaster?

A

Personnel safety

23
Q

What is the difference between an incremental and differential backup?

A

Differential takes a backup of changed files only since last full backup. Incremental takes a backup of changed files only whether it be since last full backup or last incremental backup

24
Q

What 3 things should be considered when scheduling a data backup plan?

A
  • time taken to perform backups
  • time taken to restore backups
  • procedures for restoring data
25
Q

name 4 types of data backup

A
  • Magnetic tape
  • Virtual Tape Library
  • Site replication
  • Remote backup (internet)
26
Q

What type of agreement involves a software vendor sending a copy of its software code to a third party in the event of a disaster

A

Software escrow agreement

27
Q

What are two ways of providing power during prolonged power outages?

A

UPS (Uninterrupted power supply)

Emergency electric generator

28
Q

What is another benefit of a UPS asides from continued power supply?

A

Controlled Shutdown

29
Q

What are the 5 common types of data sites?

A
Cold Site
Warm Site
Hot Site
Reciprocal Site
Multi-site
30
Q

What is a cold site in relation to a DC?

A

Empty computer room with basic environmental facilities, ie UP, heating, ventilation, etc.

31
Q

What is a warm site in relation to a DC?

A

A cold site with computers and communication links in place, but applications and business data must still be loaded

32
Q

What is a hot site in relation to a DC?

A

Second live site mirroring the primary

33
Q

What is a reciprocal site in relation to a DC?

A

agreement in place with third party that pledges availability of their DC in the event of a disaster

34
Q

What is a multi site in relation to a DC?

A

Multiple sites used to run daily operations. site is also staffed

35
Q

Which type of site provides the most rapid recovery in the event of a disaster but is also the most costly to maintain? Hot, Warm or Cold?

A

Hot

36
Q

All employees in the organisation must know about the business continuity plan. True or False?

A

True

37
Q

The salvage team is concerned with restoring full functionality to a damaged facility. What are generally the 4 steps to achieving this?

A
  1. Damage assessment.
  2. Salvage assets
  3. Cleaning
  4. Restoring facility to operational readiness
38
Q

A recovery test that includes loading data onto recovery systems without taking the production systems down is otherwise known as:

A

a parallel test

39
Q

What are the 5 basic functions that should be available after a failover (custover) test?

A
  • User Access
  • Administrative Access
  • Support
  • Integrations to other applications
  • Reporting
40
Q

What is the first step before starting a Business Continuity Plan?

A

Gaining senior management support

41
Q

How can financial risk be calculated in relation to Business Continuity?

A

P * M = C

Probability of harm * Magnitude of harm = Cost of Prevention

42
Q

Title IX of the “The Implementing The 9/11 Commission Reconsiderations Act of 2007” addresses what?

A

private sector organisations validate their readiness to recover by comparing their programs against an unnamed standard. NFPA 1600 recommended as the standard to be used.

43
Q

What os the British Standard for having a Business Continuity Plan?

A

BS25999

44
Q

What is the FFIEC BCP Booklet?

A

Federal Financial Institutions Examination Council

45
Q

Do FFIEC state that a business should be aware of the BCP plans of its third party providers?

A

Yes

46
Q

What is the US FInancial Integrity Regulatory Authority Rule 4370 (FINRA)

A

defines a minimum standard for BCP

47
Q

What are additioinal regulations on Financial Frms in relation to BCP?

A

National Association of Insurance Commissioners (NAIC)
National Futures Associatoin Compliance Rule 2-38
Electronic Funds Transfer Act
Basel committee - for banks regarding BCP
HIPAA - health

48
Q

Which country in the world was the first to introduce a standard and certification program for BCP?

A

Singapore (Standard for Business COntinuity/Disaster Recovery Service Providers (SS507)

49
Q

What is the Sarbanes Oxley Section 404?

A

Management assessment of Internal Controls. inlcudes management responsibility for maintaining financial repoting and assessment at end of yer

50
Q

In Sarbanes Oxlet what is PCAOB?

A

Public Accounting Oversight Board - responsible for BCP

51
Q

What is mobile site?

A

dc of anorganisation in a mobile trailer

52
Q

Event impacts should be categorised as following?

A

Non-incident
Incident
Severe incident